CMMCpedia Download

Requirements / Access Control (AC)

AC.L2-3.1.18

Mobile Device Connection

Official Source Material

Control connection of mobile devices.

Determine if:

  1. [a] mobile devices that process, store, or transmit CUI are identified;
  2. [b] mobile device connections are authorized; and
  3. [c] mobile device connections are monitored and logged.

Source: CMMC Assessment Guide - Level 2, Version 2.13, September 2024

Practitioner Guidance

How to meet it

Settle the definition first: phones and tablets, not laptops.

The guide defines a mobile device by small form factor, wireless operation, on-board storage, and a self-contained power source, and its examples are smart phones, e-readers, and tablets. Laptops are mobile computing platforms, addressed by AC.L2-3.1.19. An assessor may still ask about laptops here. Answer from the definition, and show laptops handled under the requirements that do govern them.

The three objectives are a list, a gate, and a log.

CUI is the controlled unclassified information your contract requires you to protect. Identify which mobile devices process, store, or transmit CUI [a], authorize connections before they happen [b], and monitor and log them [c]. A mobile device management or mobile application management platform delivers all three at once: enrollment is the identification and the authorization gate, and the console provides the monitoring and logging. Assign each device an identifier so the log entries tie back to the inventory.

Application-level management works for bring-your-own-device.

App protection policies through Intune contain CUI inside managed applications on personal phones. The container is policy-controlled, connections are authorized per app, and the platform logs them. Run the pattern from the tenant that matches your data. It satisfies the objectives from a GCC or GCC High tenant, and the personal device around the container stays out of the CUI boundary.

Prohibition is a valid answer written as met, not as not applicable.

Blocking mobile devices entirely satisfies the requirement when conditional access, the sign-in rules in your tenant, actually enforces the block. Describe the enforcement in the system security plan. A not-applicable claim asserts the situation cannot arise, which is not true of a policy that a phone can violate.

A phone that holds CUI is a CUI asset.

Management software does not demote it to a lesser asset category. If the device itself stores or processes CUI, it carries a CUI asset's obligations, which is the argument for containing CUI inside managed apps or keeping it off phones entirely.

What falls short

  • A written prohibition on mobile access with nothing enforcing it. Conditional access that still permits unmanaged phone connections leaves [b] unmet regardless of the policy.
  • Marking the requirement not applicable because mobile devices are prohibited. The prohibition is how [b] is met, so describe and evidence it as the authorization decision instead of claiming the requirement away.

Edge cases

  • Routing CUI-bearing mail to a dedicated address that phones cannot reach can take phones out of scope, but only when the restriction is technically enforced. A rule that relies on everyone following it fails the first time someone does not.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.